Detailed analysis of captured phishing page
No screenshot available
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T1DF6308BC42521A8EB03BC5C7BA61BB2CC131538ADF770DD9F6E63022D7DD86901A55B8 |
|
CONTENT
ssdeep
|
768:MRJnTAR3scHoRdXXFTo0g4ZrS/nTAR3s/yyCbLjQWBf4H4QVgU:MrTNGudnmMm/TNYkWBWn |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
cb25359e39bc2613 |
|
VISUAL
aHash
|
032020787c3c3c08 |
|
VISUAL
dHash
|
3a4ac9f2e9e9783a |
|
VISUAL
wHash
|
03206878fcfebe1c |
|
VISUAL
colorHash
|
31000000000 |
|
VISUAL
cropResistant
|
cb8b2b2b2b2babcd,9811333a9cc4569b,f25654542c5a928a,f08094373380a2f0,3a4ac9f2e9e9783a |
• Ameaça: Coleta de credenciais / Phishing
• Alvo: Usuários gerais
• Método: Envio de formulário com JS ofuscado
• Exfil: Backend desconhecido
• Indicadores: Ofuscação, branding genérico
• Risco: Alto
The site uses obfuscated JavaScript to capture input data when users interact with CTA buttons or forms.
Uses vague, pseudo-professional terminology to build false trust.